ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Cisco patches Nexus and IOS XR flaws

Cisco issued fixes for a Nexus 9000 switching flaw that could let a reachable attacker run code as root, and for an IOS XR hardening release covering seven grouped CVEs.

The Hacker News

Cisco patched a flaw in 10 Silicon One-based Nexus 9000 switch models. The advisory said a service exposed on TCP ports 43210 and 43211 in the default Layer 3 VRF could accept crafted input and execute it with root privileges, and that a failed attempt could crash S1HAL and reload the device.

Cisco said on 2 September that it had not seen abuse of the issue. It told customers to use Software Checker, an infrastructure ACL that blocked the two ports, or the temporary Live Protect shield lp00031 while fixed releases were confirmed.

Cisco also published an IOS XR hardening release that grouped seven CVEs by weakness class. It said two scored 9.8 and five scored between 8.2 and 8.8, and that 111 IOS XR releases were affected, with 14 already covered by SMUs, four waiting for SMUs and 93 needing an upgrade first.

The XR7 (LNT) platforms named in the advisory included Cisco 8000 Series, NCS 1010, NCS 540L and NCS 5700 Series. Cisco also fixed S/MIME decryption flaws in Secure Email and a denial-of-service bug in Desk Phone 9800, IP Phone 7800, IP Phone 8800 and Video Phone 8875 devices registered to Unified Communications Manager.

Separately, Sygnia said Fire Ant had used IOS XR router implants that hid syslog output, filtered show-command results and supported a concealed GRE tunnel. It said it had not identified the first access path.

Named in this story

People

Russ Smoak
was Cisco's vice president of information security

Companies

Cisco
released the patches and advisories
Sygnia
reported the Fire Ant investigation

Organisations

Fire Ant
was the China-nexus threat actor Sygnia described

Products and systems

Nexus 9000
was the switch family affected by CVE-2026-20212
NX-OS
was the switch operating system whose releases were listed as affected
IOS XR
was the router operating system covered by the hardening release
Secure Email
was the mail product with S/MIME flaws fixed the same day
Desk Phone 9800
was a phone line with a denial-of-service flaw fixed
IP Phone 7800
was a phone line with a denial-of-service flaw fixed
IP Phone 8800
was a phone line with a denial-of-service flaw fixed
Video Phone 8875
was a phone line with a denial-of-service flaw fixed
Unified Communications Manager
was the system those phones were registered to
Cisco 8000 Series
was among the XR7 platforms with a dedicated SMU
NCS 1010
was among the XR7 platforms named in the SMU notes
NCS 540L
was among the XR7 platforms named in the SMU notes
NCS 5700 Series
was among the XR7 platforms named in the SMU notes
Live Protect shield lp00031
was the temporary mitigation Cisco offered for the Nexus issue

How the source tells it

A largely technical advisory, but it repeatedly uses criticality, root-level impact and time-sensitive mitigation language to create alarm, while tempering it with no-abuse and stopgap notes.

  • alarm critical severity and root-level code execution framing
  • urgency repeated upgrade, mitigation and no-workaround guidance
  • reassurance explicit no-abuse note and temporary defences